Bump adm-zip from 0.5.10 to 0.6.0#470
Conversation
Bumps [adm-zip](https://github.com/cthackers/adm-zip) from 0.5.10 to 0.6.0. - [Release notes](https://github.com/cthackers/adm-zip/releases) - [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md) - [Commits](cthackers/adm-zip@v0.5.10...v0.6.0) --- updated-dependencies: - dependency-name: adm-zip dependency-version: 0.6.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Test Results 12 files ±0 7 129 suites - 2 1h 55m 39s ⏱️ + 10m 46s For more details on these failures, see this check. Results for commit 3ebc84b. ± Comparison against base commit 71fac53. ♻️ This comment has been updated with latest results. |
|
Hi @SiyaoIsHiding , @jorgebay This issue is currently showing up in our security scans. Could you please publish a new npm release after this PR is merged so users can get the fix via npm? Thanks! |
SiyaoIsHiding
left a comment
There was a problem hiding this comment.
LGTM. This adm-zip is a dependency of this project, not only a development dependency, so it's shipped to our users.
And this version bump includes a fix for a CVE, so it resolves a security risk for our users. Agree that we should publish a release after this gets merged.
Bumps adm-zip from 0.5.10 to 0.6.0.
Release notes
Sourced from adm-zip's releases.
... (truncated)
Changelog
Sourced from adm-zip's changelog.
... (truncated)
Commits
2b4d840updated minimum node engine version to >= 14dc57f0fHardened entry-name lookup, fixed test(), and sped up entry sortingf81806aMade utimes best-effort so it can't abort extraction (#379)ab04324Fixed extractEntryTo flattening subdirectories (#306)8a5d9baFixed empty name for directory entries (#466)3e72790Fixed uncaught crash in writeFileToAsync on write failure (#470, #459, #402)651ae4cAdded typescript typese72021dFixed infinite recursion on symlink loops in addLocalFolder (#541)8f3176bFixed directory permissions on linux4d2c8f9Fixed error introduced with zip descriptor checksDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.